Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

61–70 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#61
post #55

I use a prepaid card online, which would have been a good safety net against things like this Also he was able to get a refund, and i think in most places online, you can cancel the order

You don't get cash back bonuses with a pre-paid card. In fact, they cost money. I am not going to give up saving 3% on everything I buy just to avoid this rare error that was easily corrected for no lost money.

Re: Substack's UI and 1Password temporarily cost me $2k

#62
post #4

I'd say it's more like 1Password cost you $2,023.

Every single other website I've purchased from has a "confirm your order" page. Instantly charging the customer's card after submitting the payment form is a headache for both customers and merchants, because it's easy to make mistakes.

Re: Substack's UI and 1Password temporarily cost me $2k

#63
post #27
post #14

Earlier quoted context omitted.

It’s not 1Password fault, but poor design and implementation. :-)

The poor design and implementation of 1Password, you mean.

Speaking from personal experience -- over about six years at this point -- there are many, many web sites on the internets that 1Password's autofill works perfectly well on, and many others where it doesn't work perfectly but fails gracefully (or at least non-destructively). "Here is one site where it makes a mistake that could be catastrophic if you don't catch it" is just not a slam-dunk proof of 1Password being "poorly designed."

Re: Substack's UI and 1Password temporarily cost me $2k

#65
post #2

I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)

Or 1Pass does a little bit more smart in checking before randomly entering text? It wouldn't be difficult to catch this

Re: Substack's UI and 1Password temporarily cost me $2k

#66

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

Similar situation here. I use 1Password every day, but I only trust it to autofill simple login forms. Where something more complex is happening, I tend to copy information over field by field. This was trained into me over the years as I saw 1Password do too many things that were wrong or even sometimes scary. The nominal benefit you get sometimes when it works properly isn't worth it. And yes, web providers should…

Mock me if you wish, but I tend to use 1Password for what it does best but use Apple’s Autofill for credit cards. It misses stuff sometimes but -fingers crossed - no issues with mis population into amount fields. I also use ApplePay or PayPal wherever possible to avoid data entry and reduce friction.

Re: Substack's UI and 1Password temporarily cost me $2k

#67

Earlier quoted context omitted.

Password managers aren't nearly intelligent enough to be used without copy and paste for sensitive forms. One example is how almost every password manager including the built-in one in most browsers will assume that if there's a type="password" field, then the previous sibling field must be the username. Sometimes they'll even pick a field far away in the DOM like your chatbox input to autofill with the username. So…

I find that both Bitwarden (personal use) and 1password (work use) do a very good job of filling in login forms.

1Password was one of my test extensions and the one I use every day. It works most of the time because username/password combos are the most common autofill configurations.

So common that most password managers don't consider the case where you want to autofill a password without a matching username field on the page. "Password confirmation" being the classic example.

They just don't handle anything other than the main case very well.

Re: Substack's UI and 1Password temporarily cost me $2k

#68
post #55

I use a prepaid card online, which would have been a good safety net against things like this Also he was able to get a refund, and i think in most places online, you can cancel the order

You don't get cash back bonuses with a pre-paid card. In fact, they cost money. I am not going to give up saving 3% on everything I buy just to avoid this rare error that was easily corrected for no lost money.

Where are you getting 3% back on all transactions?

Re: Substack's UI and 1Password temporarily cost me $2k

#69
post #55

I use a prepaid card online, which would have been a good safety net against things like this Also he was able to get a refund, and i think in most places online, you can cancel the order

My bank set up a free sub-account with its own debit card that I use exclusively for online transactions.

I keep a small amount of cash in it at any time, and then do an instant transfer from my main account as needed for larger purchases. If that CC# were to get hacked, it would be annoying but not catastrophic.

Inconvenience level is pretty minimal and it’s served me pretty well.

Re: Substack's UI and 1Password temporarily cost me $2k

#70
post #34

Earlier quoted context omitted.

To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.

Yes, password managers are way safer than copy-pasting. You don't want something as sensitive as a password in your clipboard buffer, either.

Mine clears the clipboard after 10 seconds.
Post reply on HN